CVE-2006-4326

Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:justsystem:formliner:*:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:9.0:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:10.0:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:11.0:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:12.0:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:13.0:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:2004:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:2005:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro:2006:*:*:*:*:*:*:*
cpe:2.3:a:justsystem:ichitaro_government:2006:*:*:*:*:*:*:*

History

21 Nov 2024, 00:15

Type Values Removed Values Added
References () http://secunia.com/advisories/21552 - Vendor Advisory () http://secunia.com/advisories/21552 - Vendor Advisory
References () http://www.justsystem.co.jp/info/pd6002.html - Patch () http://www.justsystem.co.jp/info/pd6002.html - Patch
References () http://www.securityfocus.com/bid/19550 - () http://www.securityfocus.com/bid/19550 -
References () http://www.symantec.com/enterprise/security_response/weblog/2006/08/justsystems_ichitaro_0day_used.html - () http://www.symantec.com/enterprise/security_response/weblog/2006/08/justsystems_ichitaro_0day_used.html -
References () http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-081615-5201-99 - () http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-081615-5201-99 -
References () http://www.vupen.com/english/advisories/2006/3332 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/3332 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/28484 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/28484 -

Information

Published : 2006-08-24 01:04

Updated : 2024-11-21 00:15


NVD link : CVE-2006-4326

Mitre link : CVE-2006-4326

CVE.ORG link : CVE-2006-4326


JSON object : View

Products Affected

justsystem

  • ichitaro
  • formliner
  • ichitaro_government
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer